GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
92 advisories
Filter by severity
Insecure Permission vulnerability in TotalAV v.6.0.740 allows a local attacker to escalate...
High
Unreviewed
CVE-2024-31771
was published
May 14, 2024
A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.
Moderate
Unreviewed
CVE-2024-27460
was published
May 14, 2024
IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could...
High
Unreviewed
CVE-2024-27273
was published
May 7, 2024
In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted...
High
Unreviewed
CVE-2024-27453
was published
May 3, 2024
Kubelet Incorrect Privilege Assignment
Moderate
CVE-2019-11245
was published
for
k8s.io/kubernetes/cmd/kubelet
(Go)
Apr 24, 2024
Various software builds for the following TCL devices (30Z, A3X, 20XE, 10L) leak the device IMEI...
High
Unreviewed
CVE-2023-38298
was published
Apr 22, 2024
An issue in sanluan flipped-aurora gin-vue-admin 2.4.x allows an attacker to escalate privileges...
Moderate
Unreviewed
CVE-2024-31760
was published
Apr 17, 2024
A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers...
High
Unreviewed
CVE-2024-20320
was published
Mar 13, 2024
An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with...
High
Unreviewed
CVE-2023-50437
was published
Feb 29, 2024
An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low...
Moderate
Unreviewed
CVE-2024-25083
was published
Feb 16, 2024
In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL...
High
Unreviewed
CVE-2023-40109
was published
Feb 16, 2024
When running in Appliance mode, an authenticated attacker assigned the Administrator role may be...
Moderate
Unreviewed
CVE-2024-23976
was published
Feb 14, 2024
Incorrect Privilege Assignment vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R...
Moderate
Unreviewed
CVE-2023-6815
was published
Feb 13, 2024
A privilege escalation vulnerability was reported in some Lenovo tablet products that could allow...
Moderate
Unreviewed
CVE-2023-5080
was published
Jan 19, 2024
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom...
High
Unreviewed
CVE-2023-49647
was published
Jan 13, 2024
The FACSChorus software does not properly assign data access privileges for operating system user...
Low
Unreviewed
CVE-2023-29066
was published
Nov 28, 2023
Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The...
High
Unreviewed
CVE-2023-5913
was published
Nov 8, 2023
The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and...
High
Unreviewed
CVE-2023-4153
was published
Sep 13, 2023
SearchBlox before Version 9.2.1 is vulnerable to Privileged Escalation-Lower user is able to...
High
Unreviewed
CVE-2020-10129
was published
Sep 6, 2023
In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain...
High
Unreviewed
CVE-2023-39173
was published
Jul 25, 2023
AWS CDK EKS overly permissive trust policies
Moderate
CVE-2023-35165
was published
for
@aws-cdk/aws-eks
(npm)
Jun 19, 2023
This vulnerability exposes a network port in minikube running on macOS with Docker driver that...
Critical
Unreviewed
CVE-2023-1174
was published
May 24, 2023
The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to,...
High
Unreviewed
CVE-2023-1874
was published
Apr 12, 2023
text_helpers uses web link to untrusted target with window.opener access
Moderate
CVE-2020-36624
was published
for
text_helpers
(RubyGems)
Dec 22, 2022
A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension...
Moderate
Unreviewed
CVE-2022-4613
was published
Dec 19, 2022
ProTip!
Advisories are also available from the
GraphQL API